CVE-2025-59828
CRITICALDescription
Claude Code is an agentic coding tool. Prior to Claude Code version 1.0.39, when using Claude Code with Yarn versions 2.0+, Yarn plugins are auto-executed when running yarn --version. This could lead to a bypass of the directory trust dialog in Claude Code, as plugins would be executed prior to the user accepting the risks of working in an untrusted directory. Users running Yarn Classic were unaffected by this issue. This issue has been fixed in version 1.0.39. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version.
Is your site exposed to CVE-2025-59828?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| anthropic | claude_code |
References
Frequently Asked Questions
What is CVE-2025-59828? +
How severe is CVE-2025-59828? +
What products are affected by CVE-2025-59828? +
How do I check if I'm vulnerable to CVE-2025-59828? +
Related Vulnerabilities
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota plugin generate` (with …
FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in …
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution …
Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level control …
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules …
In Duck Site before version 1.0.1, the repository has a deploy workflow that runs after the build workflow completes. The …